Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8750

Опубликовано: 15 авг. 2014
Источник: redhat
CVSS2: 6

Описание

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.

A race condition flaw was found in the way the nova VMware driver handled VNC port allocation. An authenticated user could use this flaw to gain unauthorized console access to instances belonging to other tenants by repeatedly spawning new instances. Note that only nova setups using the VMware driver and the VNC proxy service were affected.

Дополнительная информация

Статус:

Important
Дефект:
CWE-367->CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1152346openstack-nova: Nova VMware driver may connect VNC to another tenant's console

6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.

nvd
больше 11 лет назад

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.

debian
больше 11 лет назад

Race condition in the VMware driver in OpenStack Compute (Nova) before ...

github
больше 3 лет назад

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.

6 Medium

CVSS2